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Amendments to the Claims; 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

1 . (Currently Amended) A method of detecting a computer malware comprising the 
steps of: 

joining an Internet Relay Chat server; 

retrieving a list of channels of the Intemet Relay Chat server; 

monitoring at least one channel in the Ust of retrieved channels[:] , by: 

joining a channel, 

waiting a time delay, 

leaving the channel, and 

simulating user activities bv transmitting a message to the channel: 
accepting data received from the monitored channel;-and 
storing and logging the data received from the monitored channe l: and 

scanning the received data to detect a computer malware . 

2.-5. (Cancelled) 

6. (Currently Amended) The method of claim [5]1, wherein the computer malware 
comprises at least one of a computer virus, a computer worm, or a computer Trojan horse 
program. 

7. (Currently Amended) The method of claim 1 , further comprising the step of: 
analyzing the stored and logged data to detect thea computer malware. 

8. (Original) The method of claim 7, wherein the computer malware comprises at least 
one of a computer vims, a computer worm, or a computer Trojan horse program. 
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9. - 14. (Cancelled) 

15. (Currently Amended) A system for detecting a computer malware comprising: 
a processor operable to execute computer program instructions; 
a memory operable to store computer program instructions executable by the 

processor; and 

computer program instructions stored in the memory and executable to perform 
the steps of: 

joining an Intemet Relay Chat server; 

retrieving a list of channels of the Intemet Relay Chat server; 

monitoring at least one channel in the list of retrieved channels[:] , by: 

joining a channel 

waiting a time delay. 

leaving the channel and 

simulating user activities by transmitting a message to the channel 
accepting data received from the monitored channel;-aHd 
storing and logging the data received from the monitored channel : and 
scanning the received data to detect a computer malware . 



16. -19.(Cancelled) 

20. (Currently Amended) The system of claim [ 1 9] 15 , wherein the computer malware 
comprises at least one of a computer virus, a computer worm, or a computer Trojan horse 
program. 

21 . (Currently Amended) The system of claim 1 5, fiirther comprising the step of: 
analyzing the stored and logged data to detect thea computer malware. 

22. (Original) The system of claim 2 1 , wherein the computer malware comprises at least 
one of a computer virus, a computer worm, or a computer Trojan horse program. 
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23. - 28. (Cancelled) 

29. (Currently Amended) A computer program product embodied on a computer 
readable medium for detecting a computer malware comprising: 

a comput e r r e adabl e m e dium; 

computer program instructions, recorded on the computer readable medium, 
executable by a processor, for performing the steps of 
joining an Litemet Relay Chat server; 
retrieving a list of channels of the Intemet Relay Chat server; 
monitoring at least one channel in the list of retrieved channels[:] . by: 

joining a channel 

yyaiting a time delay, 

leaving the channel, and 

simulating user activities by transmitting a message to the channel: 
accepting data received from the monitored channel;-aRd 
storing and logging the data received from the monitored channel : and 
scanning the received data to detect a computer malware . 

30. - 33. (Cancelled) 

34. (Currently Amended) The computer program product of claim [33]29, wherein the 
computer malware comprises at least one of a computer virus, a computer worm, or a 
computer Trojan horse program. 

35. (Currently Amended) The computer program product of claim 29, fiirther 
comprising the step of: 

analyzing the stored and logged data to detect thea computer malware. 



Page 4 of 13 



AppL No. 10/076,441 

Reply to Office action of April 7, 2005 

36. (Original) The computer program product of claim 35, wherein the computer 
malware comprises at least one of a computer virus, a computer worm, or a computer Trojan 
horse program. 

37. -57. (Cancelled) 

58. (New) The method of claim 1 , wherein transmitting the message to the channel is 
utilized for triggering the computer malware in the channel to be sent. 

59. (New) The method of claim 1 , wherein the storing and logging includes storing and 
logging a receipt time of the data and a sender of the data. 

60. (New) The method of claim 1 , wherein an Intemet Relay Chat client is utilized in the 
joining, the retrieving, and the monitoring. 

61 . (New) The method of claim 60, wherein the Intemet Relay Chat client automatically 
accepts and stores the data received from the monitored channel. 

62. (New) The method of claim 61 , wherein the Intemet Relay Chat client scans the 
received data to detect the computer malware. 

63. (New) The method of claim 62, wherein the Intemet Relay Chat client collects 
statistics. 

64. (New) The method of claim 63, wherein the Intemet Relay Chat client notifies an 
administrator of the computer malware. 

65. (New) The method of claim 1, wherein the received data includes direct client-to- 
client DCC send requests. 

66. (New) The method of claim 7, wherein the analyzing is automatically performed. 
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67. (New) The method of clarni 7, wherein the analyzing is performed manually. 
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